Exemplo n.º 1
0
def new_user():
    """
    Dialog for new user.
    """
    user_db = UserDB()
    role_db = RoleDB()

    if current_user.is_authenticated() and current_user.is_active():

        is_admin = user_db.in_group(current_user, mainApp.config["ADMIN_GROUP"])

        all_activities = set()
        for m in role_db.get_roles(current_user):
            acts = role_db.get_activities(m.role_id)
            for act in acts:
                if acts[act]:
                    all_activities.add(act)

        if "new_user" in all_activities:
            user = user_db.create_temp_empty_user()
            groups = user_db.get_all_groups()

            if "cancel" in request.form:
                return redirect(request.args.get("next") or url_for("admin.admin_page"))
            elif "update" in request.form:
                password = _check_password(request.form.get("password", None), request.form.get("pcheck", None))
                user.name = _check_username(request.form.get("name", None))
                user.fullname = request.form.get("fullname", None)
                user.bio = request.form.get("bio", None)
                g = user_db.get_group(request.form.get("primary_group", None))
                user.primary_group_id = g.id
                user.active = request.form.get("active", None) == "on"
                # Validation
                if user.name is not None:
                    if password is not None:
                        if g is not None:
                            u = user_db.add(user.name, password, user.fullname, user.bio, g, user.active)
                            flash(_('User "{0}" added.'.format(u.name)))
                            return redirect(url_for("admin_user.admin_user_page", uid=u.id))
                        else:
                            flash(_("Invalid group"))
                    else:
                        flash(_("Passwords do not match!"))
                else:
                    flash(_("Username invalid"))

            return render_template(
                "admin_new_user.html",
                state=get_state(),
                user=user,
                groups=groups,
                title=_("Add new user"),
                can_edit_users=True,
                is_admin=is_admin,
                submit_button=_("Add"),
                cancel_button=_("Cancel"),
            )
        else:
            return _not_auth()

    return _not_auth()